Compliance

Last Updated: July 29, 2026 | By Mihail Sebastian | AI Dictionary

Meeting the laws, regulations, and internal rules that apply to an AI system, and producing the evidence that proves it – from GDPR to the EU AI Act.

What is Compliance?

Compliance is meeting the laws, regulations, standards, and internal policies that apply to an AI system, and being able to prove it with evidence. The proof matters as much as the behavior: a model that acts lawfully still fails an audit if nobody documented how it was trained, tested, and overseen.

How Compliance Works

Compliance runs in four steps. First, map the obligations: which rules apply depends on jurisdiction, sector, and what the system does, so an AI credit model in the EU answers to the AI Act, the GDPR, and financial supervision at once.

Second, translate obligations into controls, concrete requirements such as bias testing before release, logging of automated decisions, and human review of high-impact ones. Third, collect evidence that the controls ran: test reports, sign-offs, decision logs.

Fourth, verify, through internal review or an AI audit, that the controls exist and work. None of this is one-time work. Models drift, regulations phase in on separate timelines, and a system that was compliant at launch has to be rechecked against whatever applies to it now.

Example of Compliance

A European bank wants to deploy an AI credit-scoring model. The EU AI Act lists creditworthiness assessment of individuals as a high-risk use, which fixes the bank’s to-do list.

The team documents the training data and design choices, tests the model for accuracy and demographic bias, and sets up human review for declined applications. The system passes a conformity assessment before going live, and its decisions are logged for ongoing monitoring.

The GDPR applies in parallel, since applicants hold rights around decisions based solely on automated processing. When a supervisor later asks why a specific applicant was declined, the bank produces the documentation instead of scrambling to reconstruct it – that ability to answer is what compliance means in practice.

FAQ

What are the penalties for violating the EU AI Act?

Fines scale with the violation. Engaging in a prohibited practice carries penalties of up to €35 million or 7% of worldwide annual turnover, whichever is higher; most other violations top out at €15 million or 3%. National authorities can also order corrective action or remove a system from the market.

Who is responsible for compliance, the vendor or the organization using the AI?

Both, with different duties. Under the EU AI Act, the provider that builds a high-risk system carries most obligations, such as documentation and conformity assessment, while the deployer that uses it must operate it as intended and ensure human oversight. Buying a compliant tool does not discharge the deployer’s own duties.

Related AI terms: AI Regulation · AI Audit · Policy · AI Governance · Risk Management

Did you like the Compliance gist?

Learn about 250+ need-to-know artificial intelligence terms in the AI Dictionary.

Mihail Sebastian — Writes about AI governance, regulation, and the technology behind them. Placeholder bio — replace with a real credential line. About

Read the Governor's Letter

Stay ahead with Governor's Letter, the newsletter delivering expert insights, AI updates, and curated knowledge directly to your inbox.

By subscribing to the Governor's Letter, you consent to receive emails from AI Guv.
We respect your privacy - read our Privacy Policy to learn how we protect your information.

Browse All AI Terms A–Z

Every term in the dictionary, in alphabetical order. Jump to a letter or scroll the full list.

A

B

C

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

S

T

U

V

W

X

Y

Z